Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
Advisories
Source ID Title
EUVD EUVD EUVD-2022-4881 Spring Cloud SSO Connector, version 2.1.2, contains a regression which disables issuer validation in resource servers that are not bound to the SSO service. In PCF deployments with multiple SSO service plans, a remote attacker can authenticate to unbound resource servers which use this version of the SSO Connector with tokens generated from another service plan.
Github GHSA Github GHSA GHSA-q4q2-93pw-qwgf Issuer validation regression in Spring Cloud SSO Connector
Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

References
History

No history.

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: dell

Published:

Updated: 2024-09-17T01:06:26.892Z

Reserved: 2017-12-06T00:00:00

Link: CVE-2018-1256

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Modified

Published: 2018-05-07T16:22:00.217

Modified: 2024-11-21T03:59:28.660

Link: CVE-2018-1256

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses